Home / Resources / Frameworks / IRDAI
IRDAI cybersecurity and AI governance for insurance: the regulatory bar keeps rising
India's insurance regulator has built a layered compliance framework spanning 24 security domains, mandatory data localization, six-hour incident reporting, and board-level accountability for cybersecurity. With the 2025 Insurance Amendment Act raising penalties tenfold and a dedicated AI Governance Working Group now drafting India's first formal AI framework for insurance, every regulated entity deploying AI agents faces a compliance landscape that grows more demanding each quarter.
What IRDAI requires, and why it matters now
The Insurance Regulatory and Development Authority of India (IRDAI) is the statutory body established under the IRDAI Act, 1999 to regulate India's insurance and reinsurance industries. Since 2023, IRDAI has issued a rapid succession of cybersecurity guidelines, corporate governance regulations, data localization mandates, and crisis preparedness circulars that collectively create one of the most prescriptive compliance frameworks in Asia's financial services sector. The June 2026 announcement of a seven-member AI Governance Working Group, chaired by Sandeep K. Shukla (Director, IIIT Hyderabad) with IRDAI CISO Deepak Gaikwad as Member Convener, signals that formal, binding AI governance requirements for insurance are months away.
Rs 10 Cr
maximum penalty per violation under the 2025 Insurance Amendment Act, a tenfold increase from the previous Rs 1 crore cap
Insurance Amendment Act, 2025
6 hrs
deadline to report cyber incidents to both IRDAI and CERT-In after detection, tightened from the earlier 24-hour window
IRDAI Cyber Security Guidelines, 2023
24
security domains covered by the Information and Cyber Security Guidelines, each requiring documented controls and annual audit
IRDAI ICS Guidelines, 2023
Who must comply
Life, general, and health insurance companies
All public and private sector insurers operating in India, across life, general, and health insurance lines. The full scope of cybersecurity, corporate governance, and data localization obligations applies regardless of company size or market share.
IRDAI ICS Guidelines, 2023 & Corporate Governance Regulations, 2024
Foreign reinsurance branches
Foreign reinsurance branches (FRBs) operating in India are subject to the same cybersecurity and data governance framework as domestic insurers, including mandatory data localization and incident reporting to IRDAI and CERT-In.
IRDAI ICS Guidelines, 2023
Insurance intermediaries
Insurance brokers, corporate agents, web aggregators, insurance marketing firms, Insurance Self-Network Platforms (ISNPs), and Common Service Centres (CSCs). Individual agents and surveyors face limited applicability but must follow minimum internal security frameworks established by their principal insurers.
IRDAI ICS Guidelines, 2023 & Policyholders' Regulations, 2024
TPAs and service providers
Third Party Administrators, Motor Insurance Service Providers (MISPs), corporate surveyors, insurance repositories, and the Insurance Information Bureau of India. All entities within IRDAI's regulatory perimeter carry cybersecurity compliance obligations, and outsourcing arrangements face mandatory IRDAI inspection access.
IRDAI ICS Guidelines, 2023 & Outsourcing Regulations, 2024
AI system deployers across insurance
All AI and ML systems used for underwriting, claims processing, fraud detection, and customer service fall under existing regulatory obligations. The IRDAI AI Governance Working Group (announced June 2026) is drafting India's first formal AI governance framework for insurance, covering pre-deployment validation, post-deployment monitoring, and accountability for automated decisions.
IRDAI AI Governance Working Group, June 2026 & DPDP Act, 2023
What you must do
Board-level cybersecurity governance and CISO independence
ICS Guidelines, 2023 & Corporate Governance Regulations, 2024. The Board of Directors holds ultimate responsibility for information security and must approve the Information and Cyber Security Policy annually. A dedicated Chief Information Security Officer (CISO) must have direct access to the Board and CEO, establishing structural independence from operational IT teams. The Information Security Risk Management Committee (ISRMC), comprising the CTO, CISO, CRO, CSO, and CHRO, must meet at least twice annually and develop a three-year cybersecurity roadmap. A separate Risk Management Committee, chaired by an independent director, must meet at least four times per year.
→ Nexovern provides the continuous, correlated telemetry that boards and CISOs need for informed oversight, covering every AI system's runtime behavior, data access patterns, and policy adherence across the organization.
Six-hour incident reporting to IRDAI and CERT-In
ICS Guidelines, 2023 & Cyber Crisis Preparedness Circular, March 2025. All cyber incidents must be reported to both IRDAI and CERT-In within six hours of detection. Policyholder notification is mandatory for personal data breaches, with a 72-hour notification window under the DPDP Act. Entities must pre-empanel certified forensic experts to investigate incidents immediately. A conflict-of-interest safeguard prohibits organizations from conducting their own forensic investigations after identifying cyber risks. All system clocks must be synchronized with India's official NTP servers for forensic accuracy.
→ When an incident involves AI systems, Nexovern's prompt-level and OS-layer telemetry answers "what data was accessed, by which agent, and when" within the six-hour reporting window, replacing forensic guesswork with correlated evidence.
Data localization and 180-day log retention
Maintenance of Information Regulations, 2025. All ICT infrastructure logs, critical data, and business data must be stored on servers physically located in India. ICT and application logs require a continuous 180-day rolling retention period within Indian jurisdiction. When activities are outsourced to service providers outside India, all original policyholder records must continue to be maintained domestically. Cloud services are permitted only if customer data is encrypted, the cloud provider meets IRDAI-acceptable security standards, and the insurer retains full control and auditability.
→ Nexovern's monitoring identifies which AI agents send data to external endpoints, providing the visibility needed to verify that data localization requirements are met and that no AI workflow routes policyholder data outside Indian jurisdiction.
Annual cybersecurity audits across 24 security domains
ICS Guidelines, 2023. Independent cybersecurity audits covering all 24 security domains are mandatory every year. Audit reports must include findings summaries, non-compliance areas, risk ratings, and compliance checklists. Submission is due within 90 days after financial year-end or 30 days from audit completion, whichever is earlier. The 24 domains span data classification, access control, asset management, cryptographic controls, cloud security, incident management, business continuity, third-party provider management, mobile security, remote work, and monitoring and logging, among others.
→ Nexovern's continuous runtime records feed directly into annual audit engagements, providing auditors with correlated evidence of AI system behavior, access patterns, and control effectiveness across the 24 security domains.
AI governance: explainability, manual review, and outsourcing restrictions
DPDP Act, 2023 & Policyholders' Regulations, 2024. Under the DPDP Act, individuals affected by automated decisions have a right to explanation and a right to manual review. Under the Policyholders' Regulations, underwriting and claims decision-making functions cannot be outsourced, meaning AI systems making these decisions must operate under the insurer's direct governance. The AI Governance Working Group is designing pre-deployment validation and post-deployment monitoring requirements that will formalize accountability when automated systems produce errors in claims outcomes, fraud flags, or underwriting decisions.
→ Nexovern captures the full decision path for every AI-driven underwriting and claims interaction, providing the evidence trail that explainability requirements demand and supporting manual review processes with complete context.
DPDP Act alignment: consent, purpose limitation, and breach notification
DPDP Act, 2023 & Regulatory Sandbox Regulations, 2025. IRDAI's Regulatory Sandbox 2025 explicitly mandates DPDP Act compliance as a prerequisite for sandbox approval. Insurers must obtain explicit, informed consent before data collection or processing. Data may be collected only for specific purposes, and secondary use requires fresh consent. AI training data must be collected with appropriate consent. All data used by AI systems, including model outputs and decision logs, must be stored in India, and customer data processed by AI must be encrypted.
→ Nexovern's session-level records show whether each AI agent processed data only for the consented purpose, providing the evidence trail that purpose limitation and DPDP alignment demand.
Penalties for non-compliance
Rs 1 lakh to Rs 5 lakhs per day, capped at Rs 10 crore
For default in furnishing documents, non-compliance with IRDAI directions, or failure to maintain solvency margin. The 2025 Insurance Amendment Act raised the cap tenfold from the previous Rs 1 crore limit, with penalties accumulating daily for continuing defaults.
Insurance Act, 1938 (as amended 2025), Section 102
Rs 1 crore to Rs 5 crore for false information
Providing false information to IRDAI attracts a minimum penalty of Rs 1 crore, extending to Rs 5 crore for each instance of failure. The 2025 Amendment also grants IRDAI express power to order disgorgement of wrongful gains.
Insurance Amendment Act, 2025
Board supersession and license action
IRDAI can supersede an insurer's board and appoint an administrator. The composite licensing framework now allows license suspension as a remedial step before permanent revocation, giving IRDAI a graduated enforcement toolkit. Procedural safeguards require IRDAI to consider nature, gravity, duration, and repetitiveness before imposing penalties.
Insurance Amendment Act, 2025
Recent enforcement actions
Policybazaar Insurance Brokers received a Rs 5 crore penalty (August 2025) for 11 charges including biased product promotions and governance violations. Cybersecurity breach penalties totaling Rs 3.3 crore were imposed in July 2025. Tata AIG and LIC are under investigation for separate data breach incidents. Appeals may be filed before the Securities Appellate Tribunal (SAT) within 45 days.
IRDAI Enforcement Orders, 2024-2025
Key dates
01
April 24, 2023: Information and Cyber Security Guidelines
IRDAI issues comprehensive cybersecurity guidelines covering 24 security domains, mandating board-level accountability, CISO independence, six-hour incident reporting, and 180-day log retention. Governance and reporting requirements take effect immediately.
02
March 20, 2024: Corporate Governance Regulations
IRDAI notifies the Corporate Governance for Insurers Regulations, 2024, formalizing governance structures, mandatory board committees, quarterly meeting cadences, and minimum three independent directors. Compliance deadline for the accompanying Master Circular is June 30, 2024.
03
January 10, 2025: Regulatory Sandbox and Data Maintenance
IRDAI notifies the Regulatory Sandbox Regulations 2025, permitting controlled experimentation with AI/ML, blockchain, and chatbots while mandating DPDP Act compliance as a prerequisite. Simultaneously, the Maintenance of Information Regulations consolidate data governance and mandate India-based data centres.
04
February 5, 2026: Enhanced penalties operative
The Insurance Amendment Act, 2025 (receiving Presidential assent on December 20, 2025) commences, raising the maximum penalty from Rs 1 crore to Rs 10 crore and granting IRDAI disgorgement powers. Penalties fund the newly established Policyholders' Education and Protection Fund.
05
April 1, 2026: Fraud Monitoring Framework effective
The Fraud Monitoring Framework Guidelines, issued October 2025, take effect. The framework governs AI-assisted fraud detection oversight, requiring audit trails, explainability, and false-positive management for automated fraud systems.
06
June 19, 2026: AI Governance Working Group announced
IRDAI announces a seven-member working group chaired by Sandeep K. Shukla (Director, IIIT Hyderabad) with IRDAI CISO Deepak Gaikwad as Member Convener. The group is tasked with delivering India's first formal AI governance framework for insurance within three months.
07
~September 2026: AI governance recommendations expected
The Working Group's three-month deadline for delivering recommendations covering ethical AI use, pre-deployment audits, post-deployment monitoring, stress testing for AI models, and security controls against AI-driven automated attacks.
How Nexovern helps
- Continuous AI system visibility: Discover every AI agent and ML model operating across the insurance environment, with identity-correlated records of what data each session accessed, which decisions it influenced, and where outputs were routed.
- Six-hour incident forensics: When a cyber incident involves AI systems, Nexovern's correlated app-layer and OS-layer telemetry answers "what happened, which system, what data, and when" within the six-hour IRDAI and CERT-In reporting window.
- Data localization compliance: Visibility into which AI agents send data to external endpoints, supporting verification that policyholder data, decision logs, and AI model outputs remain within Indian jurisdiction as the Maintenance of Information Regulations require.
- Audit readiness across 24 security domains: Continuous runtime evidence on access control, data classification, encryption, incident management, and monitoring feeds directly into the annual independent cybersecurity audit, reducing the manual assembly of compliance evidence.
- AI governance readiness: Capture the full decision path for every AI-driven underwriting, claims, and fraud detection interaction, building the evidence base that the AI Governance Working Group's forthcoming framework will demand for pre-deployment validation and post-deployment monitoring.
- Explainability and manual review support: Session-level records reconstruct how AI agents reached specific decisions, supporting the DPDP Act's right to explanation and manual review obligations for automated decisions affecting policyholders.
- Third-party vendor oversight: Monitor AI systems sourced from vendors and cloud providers, ensuring that outsourced AI workflows meet IRDAI's security standards and that the insurer retains full auditability regardless of where the technology was developed.
IRDAI compliance for AI in insurance starts with knowing what you have
Every AI agent processing policyholder data in your environment is within scope. A Nexovern demo shows you where your AI systems operate today, what data they touch, and where the gaps are before the AI Governance Working Group's recommendations become binding.